November 2004 Archives

Phishing the hosts

November 8, 2004 2:16 PM | 3 Comments

A new and more stealth phishing scam has entered the Internet scam market. According to this link, scammers are now able to manipulate the hosts files in users' computers, thus redirecting them to their nefarious Web sites without the user ever realizing it. This is mainly done with script-laden emails, some of which may not even require users clicking on any links – just opening the email is enough.

Frankly I am surprised that it took this long for scammers to employ this trick. But abolishing the hosts file, as some experts might suggest, is not a solution to curb the crackers using this trick. First of all hosts files are still legitimate means of translating names into ip addresses. I bet many organizations still use them internally as a quick and simple DNS alternative. Secondly, hosts files are invaluable for debugging. I can't tell you how many times I have used the hosts file to troubleshoot DNS problems, access issues, or other host name related quirks. Without the hosts file, I would have had to tinker with a name server which is a lot more complex and may itself be the root of the problem.

Finally, who's to say the bad actors won't change the computer's DNS entries to point to their own evil name servers. If they can change the hosts files, modifying DNS entries takes just a little more work.

Let's not eliminate a helpful tool out of fear and desperation. Practicing good security is the only way to fight these types of attacks.

December 2008

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

Technorati

Technorati search

» Blogs that link here

Powered by Movable Type 4.23-en

Recent Entries

About this Archive

This page is an archive of entries from November 2004 listed from newest to oldest.

October 2004 is the previous archive.

December 2004 is the next archive.

Find recent content on the main index or look in the archives to find all content.

Subscribe to Blog

Categories

Around TMCnet Blogs

Latest Whitepapers

TMCnet Videos